Filtered by vendor Openstreetmap Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-6572 3 Openstreetmap, Wordpress, Wpbakery 4 Openstreetmap, Wordpress, Page Builder and 1 more 2025-08-12 5.9 Medium
The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.2.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2022-4676 1 Openstreetmap 1 Openstreetmap 2025-01-09 5.4 Medium
The OSM WordPress plugin through 6.01 does not validate and escape some of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.